CVE-2025-59536, CVE-2026-21852: RCE and API Token Exfiltration Through Claude Code

Some of these have been “patched”, but CC is still very willing to execute code with minimal visibility.

The most I can let these AI agents execute is write to a txt or md file, I don’t trust them to write anything else….